Microsoft Office 365 SharePoint Sites Audit Events
Microsoft Office 365 SharePoint Sites Audit Events
The following list of audit events are supported for Microsoft Office 365 SharePoint Sites. For event description, refer to the Microsoft article.
Event Name |
---|
AccessInvitationAccepted |
AccessInvitationCreated |
AccessInvitationExpired |
AccessInvitationRevoked |
AccessInvitationUpdated |
AccessRequestAccepted |
AccessRequestApproved |
AccessRequestCreated |
AccessRequestDenied |
AccessRequestExpired |
AccessRequestRejected |
ActivationEnabled |
Add app role assignment grant to user |
Add app role assignment to group |
Add application |
Add delegation entry |
Add device |
Add domain to company |
Add external user to group. |
Add group |
Add member to group |
Add member to role |
Add OAuth2PermissionGrant |
Add owner to application |
Add owner to group |
Add owner to service principal |
Add partner to company |
Add policy |
Add policy to service principal |
Add registered owner to device |
Add registered users to device |
Add role member to Role |
Add service principal |
Add service principal credentials |
Add unverified domain |
Add user |
AddedToGroup |
AddedToSecureLink |
AdministratorAddedToTermStore |
AdministratorDeletedFromTermStore |
AllowGroupCreationSet |
AnonymousLinkCreated |
AnonymousLinkRemoved |
AnonymousLinkUpdated |
AnonymousLinkUsed |
AppCatalogCreated |
Assign external user to application. |
AuditPolicyRemoved |
AuditPolicyUpdate |
AzureStreamingEnabledSet |
Batch invites processed. |
Batch invites uploaded. |
Change user license |
Change user password |
ChannelAdded |
ChannelDeleted |
CollaborationTypeModified |
CompanyLinkCreated |
CompanyLinkRemoved |
CompanyLinkUsed |
Consent to application |
Create application password for user |
Create company |
CreateSSOApplication |
CustomizeExemptUsers |
DefaultLanguageChangedInTermStore |
Delete device |
Delete group |
Delete user |
DeleteSSOApplication |
DisableSharingForNonOwners |
eDiscoveryHoldApplied |
eDiscoveryHoldRemoved |
eDiscoverySearchPerformed |
ExemptUserAgentSet |
Failed Login |
FileAccessed |
FileCheckedIn |
FileCheckedOut |
FileCheckOutDiscarded |
FileCopied |
FileDeleted |
FileDeletedFirstStageRecycleBin |
FileDownloaded |
FileFetched |
FileModified |
FileMoved |
FilePreviewed |
FileRenamed |
FileRestored |
FileSyncDownloadedFull |
FileSyncDownloadedPartial |
FileSyncUploadedFull |
FileSyncUploadedPartial |
FileUploaded |
FileViewed |
Finish applying group based license to users |
FolderCreated |
FolderDeleted |
FolderDeletedFirstStageRecycleBin |
FolderModified |
FolderMoved |
FolderRenamed |
FolderRestored |
ForeignRealmIndexLogonCookieCopyUsingDAToken |
ForeignRealmIndexLogonInitialAuthUsingADFSFederatedToken |
GroupAdded |
GroupRemoved |
GroupUpdated |
Invite external user. |
LanguageAddedToTermStore |
LanguageRemovedFromTermStore |
LegacyWorkflowEnabledSet |
Login |
MaxQuotaModified |
MaxResourceUsageModified |
MemberAdded |
MemberRemoved |
MySitePublicEnabledSet |
NewsFeedEnabledSet |
ODBNextUXSettings |
OfficeOnDemandSet |
PageViewed |
PasswordLogonCookieCopyUsingDAToken |
PasswordLogonInitialAuthUsingADFSFederatedToken |
PasswordLogonInitialAuthUsingPassword |
PeopleResultsScopeSet |
PreviewModeEnabledSet |
QuotaWarningEnabledModified |
Redeem external user invite. |
Remove app role assignment from user |
Remove delegation entry |
Remove domain from company |
Remove eligible member from role |
Remove member from group |
Remove member from role |
Remove OAuth2PermissionGrant |
Remove owner from group |
Remove Partner from company |
Remove policy credentials |
Remove role member from Role |
Remove service principal |
Remove service principal credentials |
RemovedFromGroup |
RemovedFromSharedWithMe |
RemovedFromSiteCollection |
RenderingEnabled |
Reset user password |
ResourceWarningEnabledModified |
Restore user |
Revoke consent |
SearchCenterUrlSet |
SecondaryMySiteOwnerSet |
SecureLinkCreated |
SecureLinkUsed |
SendToConnectionAdded |
SendToConnectionRemoved |
Set Company contact information |
Set Company Information |
Set delegation entry |
Set DirSyncEnabled flag on company |
Set domain authentication |
Set federation settings on domain |
Set force change user password |
Set group license |
Set license properties |
Set Password Policy |
SharedLinkCreated |
SharedLinkDisabled |
SharingInheritanceBroken |
SharingInvitationAccepted |
SharingInvitationCreated |
SharingInvitationRevoked |
SharingPolicyChanged |
SharingRevoked |
SharingSet |
SiteAdminChangeRequest |
SiteCollectionAdminAdded |
SiteCollectionAdminRemoved |
SiteCollectionCreated |
SitePermissionsModified |
SiteRenamed |
SSOGroupCredentialsSet |
SSOUserCredentialsSet |
Start applying group based license to users |
SyncGetChanges |
TeamCreated |
TeamDeleted |
TeamSettingChanged |
Trigger group license recalculation |
UnmanagedSyncClientBlocked |
Update application |
Update device |
Update domain |
Update external secrets |
Update group |
Update policy |
Update service principal |
Update user |
UpdateSSOApplication |
UserAddedToGroup |
UserLoggedIn |
UserLoginFailed |
UserRemovedFromGroup |
Verify domain |
Verify email verified domain |
VideoRequested |
Viral tenant creation. |
Viral user creation. |
WACTokenShared |